<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk enterprise not receive any data from Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538721#M90265</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm a trial user for Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a setup in Azure: One Azure VM running Splunk Enterprise and four Azure VMs with Universal Forwarders that should send a data to Enterprise server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see those instances listed in Enterprise server in Forwarder Management, but UFs are not sending any data. Ports 9997 and 8089 are open both inbound and outbound in servers with UF and in the server running Enterprise server. Also they are opened in Azure NSG for all VMs.&lt;/P&gt;&lt;P&gt;When looking splunkd in servers with UF, the handshake is done and the enterprise server IP is accessed. When restarting UF, it shows that all is fine - port is open etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But nothing more is happened. I can't see other VMs with UF as host when searching "index = _*", only the one which is running Enterprise, i.e. itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know anymore how to troubleshoot further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Earlier it gathered events from the server running Enterprise, but not anymore. It captured 6928 events and nothing has happened after that. There is a warning as in the picture attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12828i5D3479D7FBB8EBB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk.png" alt="splunk.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2021 09:28:21 GMT</pubDate>
    <dc:creator>JakeK</dc:creator>
    <dc:date>2021-02-05T09:28:21Z</dc:date>
    <item>
      <title>Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538721#M90265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm a trial user for Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a setup in Azure: One Azure VM running Splunk Enterprise and four Azure VMs with Universal Forwarders that should send a data to Enterprise server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see those instances listed in Enterprise server in Forwarder Management, but UFs are not sending any data. Ports 9997 and 8089 are open both inbound and outbound in servers with UF and in the server running Enterprise server. Also they are opened in Azure NSG for all VMs.&lt;/P&gt;&lt;P&gt;When looking splunkd in servers with UF, the handshake is done and the enterprise server IP is accessed. When restarting UF, it shows that all is fine - port is open etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But nothing more is happened. I can't see other VMs with UF as host when searching "index = _*", only the one which is running Enterprise, i.e. itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know anymore how to troubleshoot further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Earlier it gathered events from the server running Enterprise, but not anymore. It captured 6928 events and nothing has happened after that. There is a warning as in the picture attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12828i5D3479D7FBB8EBB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunk.png" alt="splunk.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538721#M90265</guid>
      <dc:creator>JakeK</dc:creator>
      <dc:date>2021-02-05T09:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538731#M90267</link>
      <description>&lt;P&gt;Greetings&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231237"&gt;@JakeK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It sounds like you're most of the way there!&lt;/P&gt;&lt;P&gt;You clearly have gone through &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Updating/Configuredeploymentclients" target="_self"&gt;these steps&lt;/A&gt; in some way in order to get the deployment clients talking to the deployment server (your Splunk Enterprise instance). That is nice to have, but all the deployment server really does is hands out configurations to the clients and as you can see handles phoning home. This is data that goes mostly to the clients from 8089 (and minimal data comes back from the clients over the same port).&lt;/P&gt;&lt;P&gt;You now need to configure where you want the forwarders' data to go. This will be a one-way trip from the forwarders to Splunk Enterprise over 9997. &lt;A href="https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Configureforwardingwithoutputs.conf" target="_self"&gt;Here is the general documentation&lt;/A&gt; covering this, but I'll provide a quick-and-dirty example that should work with your case.&lt;/P&gt;&lt;P&gt;On a test forwarder, create the file &lt;FONT face="courier new,courier"&gt;$SPLUNK_HOME/etc/system/local/outputs.conf&lt;/FONT&gt;. In it, define the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout-server://10.11.12.321:9997]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the full documentation for outputs.conf:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf&lt;/A&gt;. You should be able to use any resolvable form (ip address, host name, or FQDN) of your Enterprise instance.&amp;nbsp; I'm not familiar enough with Azure, but I recommend using an internal IP/name just in case Azure charges egress for sending the data "externally."&lt;/P&gt;&lt;P&gt;Once complete, restart splunk with &lt;FONT face="courier new,courier"&gt;$SPLUNK_HOME/bin/splunk restart&lt;FONT face="arial,helvetica,sans-serif"&gt;.&amp;nbsp;The data should come in quickly after the forwarder is restarted.&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;P.S. Your warning is unrelated. I'm pretty sure all new Splunk installs show that when searching the internal index.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538731#M90267</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2021-02-05T10:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538733#M90268</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231237"&gt;@JakeK&lt;/a&gt;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;are you receinving Splunk internal logs from those UFs (index=_internal) or not?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;If not, there's a connection problem to analyze.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;If instead you're receiving Splunk Internal logs, it means that there's a problem in inputs configuration:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;which Technical Add-ons are you using on those UFs for ingesting?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Ciao.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538733#M90268</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-05T10:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538751#M90269</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/182087"&gt;@jacobpevans&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked outputs.conf and seems to be ok - it is connected to the Splunk server IP address port 9997. I have tested both IP address and FQDN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="outputs.png" style="width: 369px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12832i25B073A8821CFD98/image-size/large?v=v2&amp;amp;px=999" role="button" title="outputs.png" alt="outputs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also when testing with Test-Connection in PowerShell, the server machine IP and Port are accessible&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ps.png" style="width: 582px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12833i61BED2BA58625BEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ps.png" alt="ps.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Jarmo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:09:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538751#M90269</guid>
      <dc:creator>JakeK</dc:creator>
      <dc:date>2021-02-05T12:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538759#M90271</link>
      <description>&lt;P&gt;That all looks good. I don't think it's an issue, but you only need &lt;FONT face="courier new,courier"&gt;[tcpout] &amp;amp; [tcpout:groupname]&lt;/FONT&gt; &lt;STRONG&gt;OR&lt;/STRONG&gt; &lt;FONT face="courier new,courier"&gt;[tcpout-server://...]&lt;/FONT&gt;. Can you try it with just the last line in your file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, can you manually check the forwarder's logs with that configuration? The crucial log file will be:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;C:\Program Files\SplunkForwarder\var\log\splunk\splunkd.log&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;In particular, search for&lt;/FONT&gt; [ERROR] &lt;FONT face="arial,helvetica,sans-serif"&gt;and&lt;/FONT&gt; [WARN]&lt;FONT face="arial,helvetica,sans-serif"&gt;, and&lt;/FONT&gt; TCPOutputProc.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538759#M90271</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2021-02-05T12:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538778#M90278</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/182087"&gt;@jacobpevans&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed Wireshark to the server running Splunk Enterprise and the machine receives data thru port 9997 from all the forwarders. But nothing is shown in the Enterprise in Splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Jarmo&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 14:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538778#M90278</guid>
      <dc:creator>JakeK</dc:creator>
      <dc:date>2021-02-05T14:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538807#M90285</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231237"&gt;@JakeK&lt;/a&gt;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;are you receinving Splunk internal logs from those UFs (index=_internal) or not?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;If you're receiving Splunk Internal logs, it means that there's a problem in inputs configuration:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Which Technical Add-ons are you using on those UFs for ingesting?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;In addition, check the logs you have on a different date:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2nd of may for the logs of 5th of february&lt;/LI&gt;&lt;LI&gt;2nd of april for the logs of the 4th of february&lt;/LI&gt;&lt;LI&gt;2nd of march for the logs of the 3rd of february&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-align-justify"&gt;Ciao.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/538807#M90285</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-05T17:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/539098#M90317</link>
      <description>&lt;P&gt;I got it solved. I was missing the part to send UF configuration (i.e. inputs.conf) from the deployment server to UFs in my sending machines. So I did configuration partly but now it works! Thanks for your hints!&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Jarmo&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="solved.png" style="width: 928px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12851i9876FAEE8BA04CBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="solved.png" alt="solved.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 07:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/539098#M90317</guid>
      <dc:creator>JakeK</dc:creator>
      <dc:date>2021-02-09T07:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise not receive any data from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/539114#M90323</link>
      <description>&lt;P&gt;If your outputs.conf was set up properly and nothing was blocking it, the default _internal configuration still should have been sending.&lt;/P&gt;&lt;P&gt;Regardless, glad you got it figured out! Please mark your answer as the accepted answer since that resolved the initial question in case anyone else comes across this.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 09:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-enterprise-not-receive-any-data-from-Universal-Forwarder/m-p/539114#M90323</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2021-02-09T09:03:17Z</dc:date>
    </item>
  </channel>
</rss>

